There is a lot of fun offensive stuff being developed in PowerShell these days. An example is Invoke-Phant0m an excellent Microsoft Windows eventlog wiper. This post is about PSAttack, a framework which tries to include almost all Microsoft PowerShell scripts that can be used in a penetration test. Read more about PSAttack: A Offensive PowerShell Console!

Posted: 2 years ago by @pentestit4804 viewsUpdated: June 20, 2017 at 9:49 am

Malware's are always getting smarter and trying to outsmart our generic detection methodologies. One of the first ways they avoid detection is by checking if the executing environment is a virtual machine (VM). There are multiple ways to do that. Red Pill by Joanna Rutkowska, verifying memory structures such as Store Interrupt Descriptor Table (SIDT), Store Local Descriptor Read more about Antivmdetection: Thwart Virtual Machine Detection!

This short post is about Invoke-Phant0m, which "walks" thread stacks of the Event Log Service process (specifically svchost.exe), identifies them and kills Event Log Service Threads. This will render the system unable to collect system logs, while the Event Log Service appears to be running. Invoke-Phant0m is an open source Microsoft Windows based event log killer in Read more about Invoke-Phant0m: The Windows Event Log Killer!

Featured Post

Kali Linux 2019.1 is the latest Kali Linux release. This is the first 2019 release, which comes after Kali Linux 2018.4, that was made available in the month of October. This new release includes all patches, fixes, updates, and improvements since the last release – Kali Linux 2018.3, including a shiny new Linux kernel versionRead more about UPDATE: Kali Linux 2019.1 Release!